Private beta · Draft for owner and counsel review

Privacy Policy

Last updated 28 September 2026. This notice describes the current private-beta app, not a promise that every future feature is enabled.

Browsing and guest accounts

You can browse Stations without an account. When an adult accepts the in-app Contributor notice and starts contributing, Supabase silently creates a private anonymous Auth guest ID. We do not ask for a name, email, or Apple sign-in. The ID is not a durable person or device identity: reinstalling or losing the guest session can make it impossible to recover contributions or use in-app deletion. A new guest ID can evade per-guest limits.

Reports and Station requests

Availability Reports contain the Station, structured observation, submission time, and a client-supplied indication of whether an optional nearby check succeeded. Your precise coordinates remain on your phone for that check; the server receives only the result, which is not independent proof. Near Me discovery sends a rounded coarse grid centre. Public reports do not show guest IDs. Private Station Problems and missing-Station requests may include notes and suggested locations, visible to Moderators. Accepted factual Station corrections may enter the public ODbL Station Registry without guest identity or private notes.

Abuse controls and retention

Current database limits allow one report per Station per guest in 12 hours and 20 reports per guest per India calendar day. Supabase also throttles anonymous account creation. We do not use an IP address or device identifier as a durable Contributor identity. Any later network-side abuse controls require a privacy review and an updated notice. Reports are publicly shown for up to 12 months; de-identified report facts and private Station requests are deleted after 24 months. Guest moderation action and appeal audit records are deleted after one year. Non-personal Station decision provenance can remain, but Moderator IDs and free-text reasons are de-identified after 24 months. A consent record remains only while its guest session exists.

Ads, purchases, and processors

Google AdMob may show contextual ads on Station list or detail surfaces and may receive IP address, device and app information, ad interactions, and diagnostics. Personalization and publisher first-party ID are disabled; the app does not request App Tracking Transparency permission or use IDFA, and does not send guest ID or precise location to Google for ad targeting. The ad-free purchase is disabled during private beta. Verified StoreKit entitlements, if offered later, only suppress ads and are not sent to Supabase as server privileges. Supabase hosts account and report data in Mumbai; Cloudflare hosts these pages; Resend receives support and privacy email at separate beta addresses. See the processor inventory.

Deletion and requests

In Settings, Delete Guest Data removes the current guest Auth account, consent, private identity links, and private notes. Existing structured reports remain without identity as “Former Contributor” until the retention period ends. This cannot be undone. If a session is lost, in-app deletion cannot target it; see deletion instructions and privacy contact status. The unbranded beta privacy address receives requests but cannot send replies yet; the 30-day response target awaits a branded reply route and tracking.

Owner and Indian counsel review are pending. Do not treat this draft as a claim of legal compliance.